Home / Cybersecurity

Offensive & Defensive Security

Both sides of the fence — I break in as a red-teamer, then build the detections that catch exactly that behaviour.

Red TeamWazuh XDRMITRE ATT&CKActive DirectoryIncident Response
§ 01Red Team

Offensive security.

Full-scope engagements from passive reconnaissance through to domain compromise.

Red Team Intern · Cyberster

Mar 2026 — May 2026
Offensive Security · Remote
  • End-to-end penetration tests across Linux, Windows, and Active Directory labs — passive OSINT to Domain-Admin compromise.
  • OSINT and subdomain enumeration with Subfinder, Assetfinder, and OWASP Amass — 352 subdomains discovered, 21 live hosts validated via httpx & Gowitness.
  • AS-REP Roasting, Kerberoasting, LLMNR/NBT-NS poisoning, GPO ACL abuse — reaching NT AUTHORITY\SYSTEM on domain controllers.
  • Phishing campaigns with GoPhish and Havoc C2; AMSI bypass, LOLBAS, and payload obfuscation to evade endpoint defences in controlled labs.
  • Documented findings in professional pentest reports mapped to CVSS and MITRE ATT&CK.
§ 02Blue Team

Detection engineering & SOC.

Live defensive work on university infrastructure.

01 Wazuh XDR · Detection Engineering

Wazuh Deployment & Custom Rules

Deployed the Wazuh XDR platform across university infrastructure and wrote custom detection rules for threat detection and automated active response, tailored specifically to the university's environment and requirements — each rule and workflow properly documented for the team.

ApproachDetections are mapped to MITRE ATT&CK so alerts arrive with adversary context, and active-response actions contain threats automatically rather than waiting on manual triage.
Wazuh XDRCustom RulesActive ResponseMITRE ATT&CKLog AnalysisDocumentation
02 AI-Assisted Detection

ThreatNet — AI-Assisted SOC Detector

A supervised deep-learning detector classifying enterprise network flows into benign traffic plus five attack behaviours — reconnaissance, brute force, web attack, exfiltration, and botnet C2 — with a GRU host-log model extending coverage to Linux authentication sessions.

0.9994Macro-F1
30KFlows classified
43Incidents auto-raised
PythonTensorFlowGRUKali Linux
§ 03Threat Intelligence

Turning reports into detections.

03 CTI · MITRE ATT&CK · STIX 2.1

ThreatFusion AI — CTI Fusion Pipeline

An end-to-end defensive cyber-threat-intelligence pipeline: it ingests CTI reporting, extracts indicators of compromise, proposes MITRE ATT&CK mappings with a supervised classifier, scores risk, assembles a knowledge graph, and exports STIX 2.1 bundles with analyst-ready reports.

The valuable findingAn honest evaluation exposed a data-leakage artefact behind a "perfect" 0.90 F1 — held-out template testing collapsed it to 0.27, so the detection backlog was rebuilt on analyst-validated labels instead of model output.
60Reports processed
362STIX objects
85·302Graph nodes·edges
PythonMITRE ATT&CKSTIX 2.1MISP / OpenCTIKnowledge Graphs
§ 04Toolkit

Security skills.

Offensive

Red Team · Recon
NmapMetasploitBurp SuiteBloodHoundMimikatzSubfinderOWASP AmasshttpxGowitnessOSINTKerberoastingAS-REP RoastingHavoc C2GoPhishAMSI BypassLOLBAS

Defensive

Blue Team · SOC
Wazuh XDRCustom Detection RulesActive ResponseWiresharkLog AnalysisAlert TriageIncident ResponseMITRE ATT&CKCisco ASA

Security Scripting

Python-first
PythonActive Defense ScriptingC2 & Exfiltration ToolingAutomationBashPowerShell
§ 05Credentials

Security certifications.

Click a certificate name to view it.

Google · Coursera · Dec 14, 2025
Cisco Networking Academy / ICSDFA · Completed 10 May 2026
Infosec · Coursera · Nov 26, 2025
Infosec · Coursera · Nov 23, 2025
AVAILABLE FOR SOC · RED TEAM · NETWORK ROLES

Let's talk security.

Available for SOC analyst, detection engineering, and penetration testing roles.